Skip to content

fix(DATAGO-136673): bump urllib3 2.6.3 -> 2.7.0 for CVE-2026-44431/44432#153

Merged
ziyanwan merged 1 commit into
mainfrom
ziyang/DATAGO-136673/urllib3-vuln-fix
May 20, 2026
Merged

fix(DATAGO-136673): bump urllib3 2.6.3 -> 2.7.0 for CVE-2026-44431/44432#153
ziyanwan merged 1 commit into
mainfrom
ziyang/DATAGO-136673/urllib3-vuln-fix

Conversation

@ziyanwan

Copy link
Copy Markdown
Collaborator

Summary

  • Bumps urllib3 pin from 2.6.3 to 2.7.0 to fix two BLOCKING FOSSA vulnerabilities flagged on the SAM vuln dashboard:
  • Strict urllib3==2.6.3 pin currently caps the version downstream in solace-agent-mesh (and enterprise), preventing the fix from being picked up via uv lock. Bumping here unblocks the downstream fix.

Test plan

  • CI passes
  • Downstream solace-agent-mesh uv lock resolves urllib3 to 2.7.0 after this is merged and version bumped

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Signed-off-by: ZiyangWang <ziyang.wang@solace.com>
@github-actions

Copy link
Copy Markdown

⚠️ FOSSA Guard: Licensing (SolaceLabs_solace-ai-connector) • 1 flagged • 1 issue

Compared against main (15076b6a0462c638f721e97e790c0105c616bc21) • 2 new, 9 total (9 in base)

ℹ️ Privacy mode enabled - detailed violation information hidden.

  • Flagged by Policy: 1 issue(s)
  • Other: 1 issue(s)

Scan Report | View Details in FOSSA

@github-actions

Copy link
Copy Markdown

✅ FOSSA Guard: Vulnerability (SolaceLabs_solace-ai-connector) • PASSED

Compared against main (15076b6a0462c638f721e97e790c0105c616bc21) • 0 new, 1 total (3 in base)

Scan Report | View Details in FOSSA

@sonarqube-solacecloud

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@ziyanwan ziyanwan merged commit a5598af into main May 20, 2026
14 checks passed
@ziyanwan ziyanwan deleted the ziyang/DATAGO-136673/urllib3-vuln-fix branch May 20, 2026 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants